These release notes cover Service Mesh (ASM) releases before 2023.
December 2022
|
Feature |
Description |
Region |
Supported Istio version |
Edition |
References |
|
Adaptive configuration push optimization |
ASM provides a managed, on-demand xDS configuration push capability. It analyzes access logs in real time to identify the sidecar resource configurations that services need. This improves xDS push efficiency. |
All |
v1.15 and later |
Enterprise, Ultimate |
|
|
Custom authorization services for ASM gateways |
You can configure an external custom authorization service for an ASM gateway in a streamlined process. This simplifies integration with external authorization systems. |
All |
v1.15 and later |
Enterprise, Ultimate |
|
|
Service level objectives (SLOs) for enhanced observability |
Defining a service level objective (SLO) for an application in ASM automatically generates Prometheus rules, which you can then import into Prometheus to monitor your SLO. |
All |
v1.15 and later |
Enterprise, Ultimate |
|
|
OPA engine upgrade |
The OPA engine has been upgraded to version 0.46.1, which supports more OPA features. |
All |
v1.15 and later |
All |
November 2022
|
Feature |
Description |
Region |
Istio version |
Edition |
Documentation |
|
Support for Istio 1.15. |
Compatible with the community Istio 1.15 series and supports Kubernetes 1.21 to 1.25. |
All |
v1.15 |
All |
None |
|
Enhanced security for ASM gateways with blacklist and whitelist support. |
Supports centralized configuration of blacklists and whitelists for ASM gateways. |
All |
v1.15 and later |
Enterprise, Ultimate |
|
|
Support for TPROXY mode for inbound traffic interception. |
|
All |
v1.15 and later |
Enterprise, Ultimate |
|
|
Support for advanced configuration of distributed tracing. |
You can configure advanced distributed tracing features, such as the sampling rate and custom tags. |
All |
v1.15 and later |
Enterprise, Ultimate |
None |
|
Support for generating SLOs from Prometheus metrics. |
You can use metrics reported by Istio to define SLOs and their corresponding alert rules. |
All |
v1.15 and later |
Enterprise, Ultimate |
|
|
Support for configuring TLS versions on ASM gateways. |
You can configure TLS versions on an ASM gateway to enhance gateway security. |
All |
v1.14 and later |
Enterprise, Ultimate |
October 2022
|
Feature |
Description |
Region |
Supported Istio version |
Edition |
References |
|
CNI-based traffic redirection for enhanced security. |
|
All regions |
v1.14 and later |
Enterprise, Ultimate |
|
|
Simplified configuration for selective service discovery. |
Define the service discovery scope for Service Mesh by selecting data plane namespaces to simplify configuration and improve control plane performance. |
All regions |
v1.14 and later |
All |
|
|
Enhanced mesh topology. |
The mesh topology feature monitors network traffic to infer service topology and analyze the mesh, helping you understand the structure and health of your Service Mesh. |
All regions |
v1.14 and later |
All |
|
|
ASM security policy. |
|
All regions |
v1.14 and later |
Enterprise, Ultimate |
|
|
Enhanced observability for throttling. |
This feature extends the local throttling capability by adding metric collection settings. |
All regions |
v1.14 and later |
Enterprise, Ultimate |
|
|
Enhanced trial mode for security policies. |
You can apply security policies in trial mode, allowing ASM administrators to validate policies before they take effect. |
All regions |
v1.14 and later |
All |
|
|
Application management for edge clusters. |
You can create a managed edge cluster in the Service Mesh console and manage its applications with Service Mesh (ASM). |
All regions |
v1.14 and later |
Enterprise, Ultimate |
|
|
Traffic management in lane mode. |
Create multiple traffic-isolated environments to ensure safe releases and support the parallel development of multiple service versions. |
All regions |
v1.14 and later |
Enterprise, Ultimate |
September 2022
|
Feature |
Description |
Region |
Supported Istio version |
Edition |
References |
|
ASM Competence Center |
The ASM console now includes a Competence Center for an overview of ASM's ecosystem integration capabilities. |
All |
All |
All |
|
|
Service warm-up |
This feature lets new instances warm up before receiving traffic, ensuring a graceful service startup. |
All |
v1.14 and later |
Enterprise Edition, Ultimate Edition |
|
|
Trial run mode for security policies |
You can now apply security policies in trial run mode to validate their effects before enforcement. |
All |
v1.14 and later |
All |
|
|
Enhanced AccessLog format editing |
You can now add latency-related parameters when editing the AccessLog format for latency analysis. |
All |
All |
All |
None |
|
Sidecar proxy enhancements |
|
All |
All |
All |
|
|
Support for multiple JWT algorithms |
Request authentication now supports multiple JWT algorithms, giving administrators more flexibility. |
All |
v1.13 and later |
All |
|
|
OIDC integration for single sign-on |
You can now configure single sign-on (SSO) for applications in your mesh by using external authorization to integrate with OIDC providers. Both Alibaba Cloud IDaaS and self-managed identity providers are supported. |
All |
v1.13 and later |
All |
August 2022
|
Feature |
Description |
Region |
Supported Istio version |
Edition |
References |
|
Support for Istio 1.14 |
|
All regions |
v1.14 |
All |
|
|
zone-aware routing |
Enables zone-aware routing without modifying application code. This minimizes service-to-service latency by directing traffic to instances within the same availability zone whenever possible. |
All regions |
v1.13 and later |
Enterprise Edition, Ultimate Edition |
|
|
Enhanced ASM gateway features and an optimized UI |
|
All regions |
v1.13 and later |
Enterprise Edition, Ultimate Edition |
July 2022
|
Feature |
Description |
Region |
Supported Istio version |
Edition |
References |
|
New region |
ASM is now available in the Philippines (Manila) region. |
Philippines (Manila) |
1.13 and later |
Standard, Enterprise, and Ultimate |
|
|
Support for Istio 1.13 |
Component versions have been updated. |
All regions |
1.13 |
Standard, Enterprise, and Ultimate |
None |
|
Canary release for the Istio control plane |
You can now perform a canary release for the Istio control plane. This method provides a smoother update experience than an in-place update, ensures control plane availability, and supports quick rollbacks. Note
This feature is in canary release. |
All regions |
1.13 and later |
Enterprise and Ultimate |
|
|
Integration with Alibaba Cloud IDaaS for SSO and external authorization |
You can now use the external authorization capability of the Service Mesh to integrate with OIDC-compliant identity providers. This enables single sign-on for applications in the mesh. |
All regions |
1.13 and later |
Standard, Enterprise, and Ultimate |
|
|
Manage Istio resources with SDKs |
This release adds guides for managing Istio resources with the Go and Java SDKs. |
All regions |
All |
Standard, Enterprise, and Ultimate |
June 2022
|
Feature |
Description |
Region |
References |
|
Support for Istio 1.13.4 |
ASM supports Istio 1.13.4. This feature is in canary release. |
All regions |
None |
|
Integration with ArgoCD, Argo Rollouts, Alibaba Cloud DevOps, and Flagger |
ASM integrates with systems such as ArgoCD, Argo Rollouts, Alibaba Cloud DevOps, and Flagger to enable blue-green or canary releases for application services based on traffic management. |
All regions |
|
|
Support for Knative and traffic-based auto scaling |
ASM supports the installation and deployment of Knative and provides traffic-based auto scaling. This allows you to use Knative without maintaining Istio. |
All regions |
|
|
Support for AI services on KServe |
ASM supports AI services based on KServe, enabling capabilities like blue-green releases, canary releases, and traffic splitting between revisions for model services. It also supports serverless inference workloads with auto scaling, high scalability, and concurrency-based intelligent load routing. |
All regions |
|
|
Integration with Application Load Balancer (ALB) through an ingress gateway |
ASM supports integration with Application Load Balancer (ALB) by using an ingress gateway, making ASM available to ALB users. |
All regions |
Integrate an ASM ingress gateway with an Application Load Balancer (ALB) instance |
|
Enhanced observability |
You can enable mesh topology, Prometheus monitoring, the log center, and log dashboards for an ASM instance with a single click. The status of these features is displayed, and you are notified of any errors. This improves integration and the user experience for observability. |
All regions |
None |
|
Enhanced traffic management |
|
All regions |
|
|
Support for synchronizing namespaces and tags from Kubernetes clusters to the global namespace |
ASM supports synchronizing namespaces and tags from Kubernetes clusters to the global namespace, enabling a two-way synchronization mechanism. |
All regions |
None |
May 2022
|
Feature |
Description |
Region |
References |
|
Manage ASM instances with Terraform. |
You can now use Terraform to create and upgrade ASM instances, and manage RAM permissions. |
All regions |
|
|
Support for Istio 1.12.4 |
This release introduces a service management module for streamlined service and policy configuration. It also adds a mesh topology tool for visualizing service behavior. |
All regions |
|
|
Support for the Istio CNI plug-in |
ASM now supports the CNI plug-in to redirect traffic during pod network setup. This eliminates the need for the |
All regions |
|
|
Configure a sidecar proxy using annotations |
You can now configure sidecar proxies using annotations. This lets you modify proxy resources and configurations at the global, namespace, and workload levels for more flexible and fine-grained management. |
All regions |
|
|
Enhanced mesh diagnosis |
This release adds more diagnostic rules, helping you identify and locate a wider range of mesh issues more efficiently. |
All regions |
|
|
Enhanced observability |
ASM enhances observability with a unified dashboard for log monitoring, improved Prometheus integration, and an optimized mesh topology. |
All regions |
April 2022
|
Feature |
Description |
Region |
References |
|
Commercial release |
ASM launched its commercial Enterprise and Ultimate Editions on April 1, 2022. |
All |
|
|
Envoy filter marketplace |
ASM now supports end-to-end integration of Envoy filter templates. You can bind these templates to a workload to create custom Envoy filter extensions. |
All |
|
|
Associate or disassociate an EIP with an API server |
You can now bind an EIP to an internal API server to create a public endpoint. You can also rebind or unbind an EIP from the API server. |
All |
N/A |
|
Enhanced capabilities for ASM gateways |
ASM gateways now offer enhanced capabilities, including graceful shutdown for Classic Load Balancer (CLB) connections, IPv6 support, certificate management, and improved operations. You can now retain the CLB for a gateway, obtain the real client IP, and expose gateway services through various CLB types. |
All |
|
|
Enhanced security capabilities |
|
All |
|
|
Enhanced O&M capabilities |
The ASM console now detects alert rules that you have configured for the Pilot load balancer. You can also navigate directly from the ASM console to the monitoring page of the Pilot load balancer. |
All |
N/A |
March 2022
|
Feature |
Description |
Region |
References |
|
Control the scope of OPA proxy injection |
Use the |
All regions |
|
|
Domain name and certificate management |
Use cert-manager to issue a certificate for an ASM gateway, enabling you to access a service through the gateway over HTTPS. |
All regions |
|
|
EnvoyFilter marketplace update |
ASM now provides end-to-end support for binding EnvoyFilter templates to workloads, enabling you to create custom EnvoyFilter extensions. Use the following pre-built templates or develop your own:
|
All regions |
None |
February 2022
|
Feature |
Description |
Region |
References |
|
Support for Istio 1.12 and Kubernetes 1.22 |
ASM now supports Istio 1.12 and Kubernetes 1.22. |
All regions |
None |
|
Create an Envoy filter from an Envoy filter template |
A new plug-in center in the ASM console lets you create and manage Envoy filters using Envoy filter templates. |
All regions |
|
|
Local throttling |
ASM provides a local throttling feature to limit traffic to gateways and services. |
All regions |
January 2022
|
Feature |
Description |
Region |
References |
|
ASM gateway updates |
|
All regions |
None |
|
Enhanced ASM Professional Edition features |
|
All regions |
None |
|
Spring Cloud service management |
ASM now supports managing Spring Cloud services. |
All regions |
|
|
New regions available |
ASM is now available in the China (Guangzhou), China (Hohhot), China (Heyuan), and India (Mumbai) regions. |
China (Guangzhou), China (Hohhot), China (Heyuan), India (Mumbai) |
None |
|
Support for Istio 1.11.5 |
ASM now supports Istio 1.11.5. |
All regions |
None |
December 2021
|
Feature |
Description |
Region |
References |
|
Flexible external authorization |
You can now declare an external authorization service in a Service Mesh and apply an authorization policy to enable more flexible external authorization. |
All regions |
|
|
Automatic Sidecar resource recommendations based on access log analysis |
You can use a Sidecar resource to configure a sidecar proxy on a workload to interact only with its dependent services. This configuration can be automatically recommended based on access log analysis. |
All regions |
Use Sidecar resources automatically recommended based on access log analysis |
|
Global and namespace-level sidecar proxy configuration |
ASM now supports configuring the sidecar proxy at the global and namespace levels. |
All regions |
|
|
Custom metrics |
ASM now supports defining custom metrics at the mesh, namespace, and workload levels for targeted monitoring. |
All regions |
|
|
New dashboards for gateways and the global mesh |
From the mesh details page, navigate to Observability Management Center > Prometheus Monitoring. The Prometheus Monitoring page now provides new dashboards for monitoring gateways and the global mesh. Note
This feature is available only for Istio 1.10 and later. |
All regions |
None |
|
Support for Istio 1.10.5 |
ASM now supports Istio 1.10.5. |
All regions |
None |
November 2021
|
Feature |
Description |
Region |
References |
|
TLS acceleration with Multi-Buffer. |
Intel Multi-Buffer optimizes the performance of TLS encryption and decryption to accelerate encrypted communication between application services. |
All regions |
|
|
Selective service discovery. |
Mesh administrators can now use a global mesh configuration to optimize service discovery. This directs the control plane to discover and process only application services within specified namespaces. |
All regions |
|
|
Improved stability for gateway updates. |
In the ASM console, you can now view an ASM gateway's version and manually update it on the Upgrade Gateway page. This process improves update stability. |
All regions |
None |
|
Gateway and data plane logs |
Access the log center from the observability page in the ASM console to view detailed logs for ASM gateways and the data plane. |
All regions |
None |
|
New diagnostic check for external Envoy filters. |
The mesh diagnostics feature now includes a check for external Envoy filters in the control plane. |
All regions |
None |
October 2021
|
Feature |
Description |
Region |
References |
|
Istio resource version history |
When you update the |
All regions |
|
|
Access Istio resources through the data plane Kubernetes API |
You can now use a data plane cluster's Kubernetes API to access Istio resources managed by ASM. This lets you use the cluster's kubeconfig file to install, update, and uninstall Helm charts that contain Istio resources. |
All regions |
|
|
Cross-region failover and traffic distribution |
You can now distribute traffic across multiple regions by routing requests to different clusters based on specified weights. For disaster recovery, you can also configure cross-region failover to automatically redirect traffic from a disrupted region to healthy ones. |
All regions |
|
|
Control plane log collection and alerting |
You can now collect logs and configure alerts for the control plane. For example, you can capture logs related to configuration pushes from the ASM control plane to data plane sidecars. |
All regions |
Enable control plane log collection and alerting (ASM versions earlier than 1.17.2.35) |
|
Prometheus monitoring integration |
The ASM console is now integrated with Prometheus monitoring, allowing you to view detailed traffic metrics for services and workloads on the data plane. |
All regions |
None |
|
ASM gateway enhancements |
|
All regions |
None |
|
Enhanced access log collection |
You can now create a new Project or use an existing one for access log collection. |
All regions |
None |
September 2021
|
Feature |
Description |
Region |
References |
|
asmctl command-line tool |
The asmctl diagnostic tool detects configuration issues in ASM. |
All regions |
|
|
Graphical OPA policy management |
You can now create and manage OPA policies in the ASM console. |
All regions |
|
|
Delegate RBAC permissions |
A RAM user can now grant RBAC permissions to other RAM users. |
All regions |
None |
|
Customizable access logs |
You can now enable or disable access logs and customize their format. |
All regions |
|
|
Cross-origin resource sharing (CORS) |
You can add the |
All regions |
|
|
Graphical rule creation |
You can now create destination rules and gateway rules graphically. |
All regions |
None |
August 2021
|
Feature |
Description |
Region |
References |
|
Zero-trust security capabilities |
This release adds several zero-trust security capabilities to enhance application security. These include peer authentication, request authentication, Istio authorization policies, and fine-grained permission control based on OPA. |
All regions |
None |
|
ASM gateway enhancements |
ASM gateways now include the following enhancements:
|
All regions |
|
|
ASM console enhancements |
The ASM console has been improved. You can now graphically configure security policies and virtual service rules, define custom resources using YAML templates, and use the optimized management page for automatic sidecar injection. |
All regions |
|
|
ASM observability enhancements |
|
All regions |
July 2021
|
Feature |
Description |
Region |
References |
|
Support for multiple Consul service registries |
ASM now supports connecting to multiple Consul service registries. |
All regions |
|
|
Dynamic updates for OPA policies |
The authorization mechanism for the Service Mesh now supports dynamic updates for OPA policies. |
All regions |
June 2021
|
Feature |
Description |
Region |
References |
|
Service mesh governance for ACK Edge clusters |
ASM now supports ACK Edge clusters, enabling Service Mesh use cases in edge computing scenarios over 5G networks. ASM now provides unified governance for services across all cloud-native, heterogeneous computing infrastructures. |
All regions |
None |
|
Five new checks for mesh diagnostics |
The mesh diagnostics feature now includes the following five checks:
|
All regions |
May 2021
|
Feature |
Description |
Region |
References |
|
Canary release for routing rules |
ASM Professional Edition supports canary releases for routing rule configurations. It uses an extended custom resource definition (CRD),
This capability reduces the risks of changing routing rule configurations. You can also use this feature with Microservices Engine (MSE) to implement canary releases. |
All regions |
This feature is discontinued. |
April 2021
|
Feature |
Description |
Region |
References |
|
VirtualService delegation |
ASM now supports VirtualService delegation, allowing you to split a service's routing rules into separate resources. This reduces the risk of modifying complex routing rules. |
All regions |
|
|
GZIP data compression |
You can now enable GZIP data compression for an ASM gateway. When enabled, the gateway compresses HTTP responses to speed up responses and reduce traffic. |
All regions |
|
|
WebAssembly (Wasm)-based Service Mesh instance extension |
WebAssembly (Wasm) extends the ASM data plane. You can enable the WebAssembly-based Service Mesh instance extension in the console. |
All regions |
Use ORAS to simplify Wasm-based Service Mesh instance extensions |
March 2021
|
Feature |
Description |
Region |
References |
|
DNS proxy support. |
An ASM instance uses Kubernetes services and defined ServiceEntries to push hostname-to-IP-address mappings for all accessible services. When a Service Mesh receives a DNS query from an application, the Istio proxy transparently intercepts the query and resolves the request. You can enable or disable the DNS proxy in Service Mesh by using the console or the Alibaba Cloud CLI. This can significantly improve the performance and availability of the mesh. |
All regions |
|
|
Kernel parameter tuning for ingress gateways. |
You can tune the kernel parameters for ingress gateways. This provides more flexibility to optimize performance. |
All regions |
|
|
Read-only configurations can be enabled for CLB instances created by Service Mesh. |
The API server and Pilot CLB created by Service Mesh have read-only configurations enabled by default. This prevents accidental operations, such as modifications or deletions, and improves the availability of the Service Mesh product. |
All regions |
None |
|
Namespace synchronization between the control plane and data plane. |
To improve usability, ASM now synchronizes namespaces between the control plane and the data plane. When you add a Kubernetes cluster to an ASM instance, ASM automatically synchronizes its namespaces to the cluster. The ASM console also provides a manual synchronization option. |
All regions |
None |
February 2021
|
Feature |
Description |
Region |
References |
|
Service Mesh is generally available in 12 regions, supports Istio 1.8.3, and integrates with ACK Serverless clusters and Elastic Container Instance (ECI) pods on ACK. |
|
All regions |
|
|
Enhances ingress gateway lifecycle management and adds support for custom gateways. |
|
All regions |
Create and manage an ingress gateway by using the Kubernetes API |
|
Supports connecting to multiple service registries, simplifying microservice migration to Service Mesh. |
|
All regions |
|
|
Supports WebAssembly (Wasm) for simplified service mesh extensions. |
Service Mesh now supports OCI Registry as Storage (ORAS), simplifying Wasm-based Service Mesh extensions. |
All regions |
January 2021
|
Feature |
Description |
Region |
References |
|
New regions available |
ASM is now available in the |
All |
None |
|
One-click observability setup |
To improve |
All |
|
|
HTTP/1.0 protocol support |
By default, Envoy requires |
All |
None |
|
Ingress gateway and update process enhancements |
|
All |
None |
November 2020
|
Feature |
Description |
Region |
References |
|
Istio 1.7.5 support and availability on the international site |
ASM now supports Istio 1.7.5 and is available on the international site. |
All regions |
None |
|
Istio CNI plug-in support |
ASM now supports the Istio CNI plug-in for instances running Istio 1.7 or later. The plug-in replaces the istio-init container and eliminates the need for elevated privileges, enhancing security. |
All regions |
Due to conflicts with other CNI plug-ins, this feature is discontinued and is pending re-evaluation. |
|
Mesh topology |
Mesh topology provides a web-based graphical user interface (GUI) to view the health of your Service Mesh. |
All regions |
None |
|
Hot upgrade for the data plane (Beta) |
ASM now supports hot upgrades for the data plane, allowing you to upgrade an ASM instance's data plane without service interruptions or application impact. |
All regions |
None |
October 2020
|
Feature |
Description |
Region |
References |
|
Flexible methods to enable automatic injection. |
ASM supports multiple flexible methods for enabling automatic injection: Note
Your ASM instance must be version 1.6.8.19 or later.
|
All regions |
|
|
Kubernetes 1.18 support on the data plane. |
The ASM data plane now supports Kubernetes clusters running version 1.18, including all supported versions of ACK clusters. Note
Your ASM instance must be version 1.6.8.19 or later. |
All regions |
None |
September 2020
|
Feature |
Description |
Region |
References |
|
Support for Istio 1.6.8 |
ASM now supports Istio version 1.6.8 and provides full support for ACK-on-ECI and ACK Serverless clusters. With this update, ASM provides unified support for various types of computing infrastructure, including dedicated ACK clusters, managed ACK clusters, ACK Serverless clusters, ACK-on-ECI, ECI, ECS, and registered external clusters. |
All regions |
None |
|
Enhanced Mixerless Telemetry V2 |
ASM enhances Mixerless Telemetry V2 to non-intrusively generate telemetry data from service traffic within the service mesh. You can use these ASM metrics to automatically scale workloads. |
All regions |
|
|
Mesh diagnostics |
ASM now supports mesh diagnostics for an ASM instance. These diagnostics check data plane versions, service ports, service associations, app and version labels, destination addresses, and virtual service conflicts. This feature simplifies the operation and maintenance of your Service Mesh. |
All regions |
August 2020
|
Feature |
Description |
Region |
References |
|
Cluster domain setting |
When you create an ASM instance, you can now specify a cluster domain. The default cluster domain is cluster.local. If you add an ACK cluster that uses a custom domain to the mesh, you must set the cluster domain of the ASM instance to match. |
All regions |
None |
|
Support for ACK Serverless clusters |
You can now add ACK Serverless clusters to Service Mesh. This lets you apply unified traffic management to workloads running on elastic container instances. |
All regions |
None |
July 2020
|
Feature |
Description |
Region |
References |
|
General availability of Service Mesh |
Alibaba Cloud Service Mesh (ASM) is a fully managed Service Mesh platform that is compatible with the open source Istio Service Mesh. ASM simplifies service governance by providing features such as traffic routing and splitting, secure inter-service communication, and mesh observability. This significantly reduces development and O&M workloads. ASM is designed for core scenarios, such as hybrid clouds, multi-cloud environments, multi-cluster architectures, and the migration of non-containerized applications. It provides a unified and managed Service Mesh with the following capabilities:
|
China (Beijing), China (Hangzhou), China (Zhangjiakou), China (Shanghai), China (Shenzhen), Indonesia (Jakarta), and Germany (Frankfurt). Support for additional regions is being rolled out. |
None |
|
Export tracing data to a self-managed system |
ASM supports exporting tracing data to Managed Service for OpenTelemetry and to self-managed systems that are compatible with the Zipkin protocol. |
All regions |
|
|
Support for registered clusters |
You can register an external Kubernetes cluster in the ACK console and manage its applications with Service Mesh (ASM). |
All regions |